Application Development Blog Posts
Learn and share on deeper, cross technology development topics such as integration and connectivity, automation, cloud extensibility, developing at scale, and security.
cancel
Showing results for 
Search instead for 
Did you mean: 
Former Member
0 Kudos

Understanding authorization objects superposition


Role 1

Transaction VA02

object  V_VBAK_AAT

fields ACTVT 03 "view"

         AUART Z491 "document type"

Role 2

Transaction VA02

object  V_VBAK_AAT

fields ACTVT 02 "modify"

          AUART * "document type"

Below is the access of the user when he has the role 1 and 2.

Transaction VA02

object  V_VBAK_AAT

fields ACTVT 02 03

          AUART *

In this case the user can modify the document Z491 even when only have the activity 3 in the role 1, because in the role 2 the user have permission to modify all kinds of documents through the ACTVT *

1 Comment